Nonce structure for storage devices
    2.
    发明授权
    Nonce structure for storage devices 有权
    存储设备的随机结构

    公开(公告)号:US07797751B1

    公开(公告)日:2010-09-14

    申请号:US11389835

    申请日:2006-03-27

    IPC分类号: G06F15/16

    CPC分类号: G06F21/79 G06F21/64

    摘要: A multiple field nonce particularly suited for use in encryption algorithms associated with data storage has at least one field unique to each data storage device to avoid the possibility of the same nonce value being used to store more than one data string. Additional fields may be based on the number of times at least one encryption key is associated with the storage device and on a number assigned to the particular string of data.

    摘要翻译: 特别适用于与数据存储相关联的加密算法中的多字段随机数具有每个数据存储设备唯一的至少一个字段,以避免使用相同的随机值用于存储多个数据串的可能性。 附加字段可以基于至少一个加密密钥与存储设备相关联的次数以及分配给特定字符串数据的号码。

    Token-based encryption key secure conveyance
    3.
    发明授权
    Token-based encryption key secure conveyance 有权
    基于令牌的加密密钥安全传输

    公开(公告)号:US07971062B1

    公开(公告)日:2011-06-28

    申请号:US11403109

    申请日:2006-04-12

    IPC分类号: H04L9/32 H04L9/08

    CPC分类号: H04L9/0897

    摘要: A hand-held token for secure conveyance of encryption keys includes memory for holding a media key and at least one device key. Control logic reads the media key from memory, encrypts the media key based on the device key, and transmits the encrypted media key to a data storage device. The data storage device decrypts the encrypted media key using its own device key, which may have previously been downloaded from a token.

    摘要翻译: 用于安全传送加密密钥的手持令牌包括用于保存媒体密钥和至少一个设备密钥的存储器。 控制逻辑从存储器读取媒体密钥,根据设备密钥加密媒体密钥,并将加密的媒体密钥发送到数据存储设备。 数据存储设备使用其自己的设备密钥来解密加密的媒体密钥,该密钥可能以前从令牌下载。

    System, method and data storage device for encrypting data
    4.
    发明授权
    System, method and data storage device for encrypting data 有权
    用于加密数据的系统,方法和数据存储设备

    公开(公告)号:US07706538B1

    公开(公告)日:2010-04-27

    申请号:US11404692

    申请日:2006-04-14

    IPC分类号: H04K1/00

    CPC分类号: H04L9/00 H04L2209/30

    摘要: A system, method and data storage device for encrypting data to provide at-rest data encryption of data in the data storage device. The system includes a compression engine for receiving a host data stream packet and selectively generating a compressed data packet, and an encryption engine in electronic communication with the compression engine for receiving an unencrypted data packet from the compression engine. The unencrypted data packet comprises the compressed data packet when the compression engine generates the compressed data packet. The unencrypted data packet comprises the host data packet when the compression engine does not generate the compressed data packet. The encryption engine generates an encrypted data packet having an encrypted component corresponding to the unencrypted data packet and a set of meta data indicative of one or more characteristic of the encrypted data packet.

    摘要翻译: 一种用于加密数据以提供数据存储装置中的数据的静止数据加密的系统,方法和数据存储装置。 该系统包括用于接收主机数据流分组并选择性地生成压缩数据分组的压缩引擎,以及与压缩引擎电子通信的加密引擎,用于从压缩引擎接收未加密的数据分组。 当压缩引擎生成压缩数据分组时,未加密的数据分组包括压缩数据分组。 当压缩引擎不产生压缩数据分组时,未加密的数据分组包括主机数据分组。 加密引擎生成具有对应于未加密数据分组的加密分量和表示加密数据分组的一个或多个特性的一组元数据的加密数据分组。

    Method and system for protecting keys
    6.
    发明申请
    Method and system for protecting keys 有权
    保护钥匙的方法和系统

    公开(公告)号:US20110176675A1

    公开(公告)日:2011-07-21

    申请号:US11516885

    申请日:2006-09-07

    IPC分类号: H04L9/06

    摘要: A method of protecting a media key including obtaining the media key, obtaining an auxiliary key, calculating a split key using the media key and the auxiliary key, encrypting the split key using a wrap key to generate an encrypted split key, assembling the encrypted split key and a communication key to obtain a data bundle, and sending the data bundle to a token, where the media key is extracted from the data bundle on the token to protect data on a storage device.

    摘要翻译: 一种保护媒体密钥的方法,包括获得媒体密钥,获得辅助密钥,使用媒体密钥和辅助密钥计算分裂密钥,使用换行密钥加密分裂密钥以生成加密的分裂密钥,组合加密分裂 密钥和通信密钥以获取数据包,并将数据包发送到令牌,其中从令牌上的数据包中提取媒体密钥以保护存储设备上的数据。

    CANISTER-BASED STORAGE SYSTEM SECURITY
    7.
    发明申请
    CANISTER-BASED STORAGE SYSTEM SECURITY 审中-公开
    基于CANISTER的存储系统安全

    公开(公告)号:US20120066518A1

    公开(公告)日:2012-03-15

    申请号:US13196781

    申请日:2011-08-02

    IPC分类号: G06F12/14

    摘要: Security is provided for a data set stored in a data storage canister. The data set has a data size when received for storage within the canister. At least one data security operation is performed on the received data set to generate secure data having a secure data size that may be different than the set data size. The secure data is stored on at least one data storage device within the canister. Any information about the secure data size is kept from the data producer sending the data set for storage.

    摘要翻译: 为存储在数据存储罐中的数据集提供安全性。 当数据集被接收用于存储在罐内时,数据集具有数据大小。 对所接收的数据集执行至少一个数据安全操作以生成具有与所设置的数据大小不同的安全数据大小的安全数据。 安全数据存储在罐内的至少一个数据存储装置上。 关于安全数据大小的任何信息都保留在数据生成器发送用于存储的数据集中。

    METHOD AND APPARATUS FOR SECURELY REGISTERING HARDWARE AND/OR SOFTWARE COMPONENTS IN A COMPUTER SYSTEM
    8.
    发明申请
    METHOD AND APPARATUS FOR SECURELY REGISTERING HARDWARE AND/OR SOFTWARE COMPONENTS IN A COMPUTER SYSTEM 有权
    在计算机系统中安全地注册硬件和/或软件组件的方法和装置

    公开(公告)号:US20090122988A1

    公开(公告)日:2009-05-14

    申请号:US11939416

    申请日:2007-11-13

    IPC分类号: H04L9/14

    CPC分类号: H04L9/0825

    摘要: A system that securely registers components in a first system is presented. During operation, the first system receives a request from an intermediary system to obtain configuration information related to the components in the first system. In response to the request, the first system: (1) encrypts configuration information for the first system using a first encryption key; (2) encrypts the first encryption key using a second encryption key; and (3) sends the encrypted configuration information and the encrypted first encryption key to the intermediary system so that the intermediary system can forward the encrypted configuration information and the encrypted first encryption key to the second system, whereby the encrypted configuration information is cryptographically opaque to the intermediary system. Next, the second system uses the configuration information to register the components in the first system.

    摘要翻译: 介绍了在第一个系统中安全地注册组件的系统。 在操作期间,第一系统接收来自中间系统的请求以获得与第一系统中的组件相关的配置信息。 响应于该请求,第一系统:(1)使用第一加密密钥加密第一系统的配置信息; (2)使用第二加密密钥加密第一加密密钥; 和(3)将加密的配置信息和加密的第一加密密钥发送到中间系统,使得中间系统可以将加密的配置信息和加密的第一加密密钥转发到第二系统,由此加密的配置信息对于 中介制度。 接下来,第二系统使用配置信息来注册第一系统中的组件。

    Clustered hierarchical file services
    9.
    发明授权
    Clustered hierarchical file services 有权
    集群分层文件服务

    公开(公告)号:US07529784B2

    公开(公告)日:2009-05-05

    申请号:US11143779

    申请日:2005-06-02

    IPC分类号: G06F12/00 G06F17/01

    摘要: A system for object-based archival data storage includes an object-based storage subsystem having respective data storage devices, at least one file presentation interface that interfaces to client platforms, an administration interface having graphical user interface (GUI) and a command line interface (CLI), a meta data subsystem for storing meta data about files, and includes a virtual file subsystem having a virtual file server (VFS), a policy subsystem, and a scalable interconnect to couple the object-based storage subsystem, the at least one file presentation interface, the administration interface, the meta data subsystem, and the policy subsystem, wherein the policy subsystem provides system rules predetermined by a user for at least one of hash based integrity checking, read-only/write-ability/erase-ability control, and duplicate data treatment corresponding to files and file objects.

    摘要翻译: 一种用于基于对象的存档数据存储的系统包括:基于对象的存储子系统,其具有各自的数据存储设备,至少一个与客户端平台接口的文件呈现界面,具有图形用户界面(GUI)和命令行界面 CLI),用于存储关于文件的元数据的元数据子系统,并且包括具有虚拟文件服务器(VFS)的虚拟文件子系统,策略子系统和用于耦合基于对象的存储子系统的可伸缩互连,所述至少一个 文件呈现界面,管理界面,元数据子系统和策略子系统,其中策略子系统提供由用户预先确定的基于散列的完整性检查,只读/写能力/擦除能力 控制和复制对应于文件和文件对象的数据处理。